MEDIUM
CVE-2026-4526
CVSS
6.5
Description
In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come from a device that has already joined the network, and no information leakage back to the sender was observed.
Summary dbcve.org
In EmberZNet v9.0.2 and earlier, malformed global ZCL (Zigbee Cluster Library) messages from an authenticated device (one already joined the network) trigger out-of-bounds reads in the framework's ZCL parsing logic, causing the process to terminate.
Mitigation
Update to EmberZNet v9.0.3 or later once available; restrict network join permissions and monitor for anomalous ZCL message patterns from joined devices.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
0.44%
Probability of exploitation in next 30 days
37.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.